Vulnerability in PeopleSoft Enterprise HCM Shared Components by Oracle
CVE-2018-2878

6.1MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
19 April 2018

Summary

A vulnerability exists in the PeopleSoft Enterprise HCM Shared Components of Oracle's PeopleSoft Products, particularly impacting the Notepad subcomponent. This flaw can be easily exploited by an unauthenticated attacker with network access via HTTP. Successful exploitation requires human interaction from a third-party user, and while the vulnerability lies within the HCM Shared Components, it poses risks to additional products as well. Attackers leveraging this vulnerability may gain unauthorized rights to update, insert, or delete data within the compromised components, as well as access a range of sensitive data without permission.

Affected Version(s)

PeopleSoft Enterprise HCM Shared Components 9.2

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.